A question about Auto-Enrolment


can please me following question, thanks

i reading following article

https://technet.microsoft.com/en-us/library/cc778245(v=ws.10).aspx

at first glance seemed contradict (i think know answer want check hence post)

the article says

  • on issuance requirements tab of selected certificate template, selecting this number of authorized signatures , making value greater 1 disables subject autoenrollment based on template.
  • on issuance requirements tab of selected certificate template, selecting this number of authorized signatures , setting value 1 requires requester sign request private key valid certificate in certificate store. certificate must contain application , issuance policies specified in application policy , issuance policies lists on same tab. if appropriate certificate exists in requester's certificate store, autoenrollment signs request certificate's private key , obtains , installs requested certificate automatically.

so when comes “the number of authorised signatures” first bullet point states ‘disable’ auto-enrolment second bullet point says “obtains , installs requested certificate automatically”

what believe saying if have ‘code signing’ certificate appropriate ‘application policies (eku)’ , ‘issuance policies’ in code signing cert (e.g. match requirements of template). long code signing cert in x509 store on pc, can auto-enrol , if not have has code signing cert sign csr

is correct?

if x509 store should code signing cert be  in localmachine\personal or currentuser\personal or other?

thanks all

ernie


> ku still require 'digitalsignature' 

no, doesn't require. think this: when create certificate request efs, example, keyusage extension set keyencipherment. @ same time, key used sign reuqest authenticate data. specific case key usage doesn't matter @ all.

> correct please?

generally understanding correct, not in given case.


vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

WMI Repository 4GB limit - Win 2003 Ent Question

Change home folder default permission?

After enabling Windows Server 2012 R2 DHCP Failover Getting Packet dropped because of Client ID hash mismatch